Together AI 研究与产品博客(RSS)·· 2026-04-30AI 评分61
Together AI 复盘处置 Linux 内核漏洞 Copy Fail(CVE-2026-31431)的生产应急响应
From 732 bytes to nowhere: shutting down Copy Fail in production
AI 导读
Together AI 在生产环境中处置了 Linux 内核 crypto 子系统漏洞 Copy Fail(CVE-2026-31431),该漏洞位于 algif_aead AF_ALG 接口,允许任意非特权本地用户向系统上任意可读文件的 page cache 做精确 4 字节写入,且不改变磁盘文件、不标记脏页,可绕过传统文件完整性检查并借此提权到 root。
来源:Together AI 研究与产品博客(RSS) · together.ai